1. Introduction
VoKart POS ("the App", "we", "us") is a point-of-sale application built for Indian retail merchants. This Privacy Policy explains what data we collect, how we use it, and your rights as a user.
This policy also covers the WhatsApp voice-ordering channel: if you are a customer who places an order by sending a voice note or message to a shop on VoKart, your voice audio and message content are processed as described below (see 2.5 and 5), even if you have never installed the App yourself.
By using the App, you agree to this policy.
2. Data We Collect
2.1 Account & Identity Data
- Name, email address, and phone number (provided during registration)
- Business name, GSTIN (optional), and shop address
- Login credentials (stored securely via Keycloak OAuth2; passwords are never stored in plaintext)
2.2 Business / Transaction Data
- Products, categories, prices, and stock levels you enter
- Sales transactions, payments, and receipts you create
- Customer names, phone numbers, and credit balances you record
- Supplier information and purchase invoices
2.3 Device & Technical Data
- Device model, OS version, and app version (for crash diagnostics)
- Push notification token (FCM) — used only to deliver in-app alerts to your device
- IP address, used transiently to rate-limit requests and prevent abuse; your authentication provider (Keycloak) may separately log IP addresses on its own sign-in events
2.4 Camera Access
We access the device camera when you scan a barcode or QR code (e.g., to add a product during billing or inventory management) and, separately, when a field sales representative uploads a photo while logging a customer visit. Barcode/QR scans are not stored. Customer-visit photos ARE stored and linked to the visit record.
2.5 Microphone Access
We access the device microphone when you use the voice order feature to place an order by speaking, and a customer's voice note sent over WhatsApp is captured the same way. That audio is stored for up to 365 days from upload and then automatically deleted, and is sent to a speech-to-text and/or order-extraction AI provider to convert it into an order — see 5. Data Sharing for which providers, and under what conditions. (This 365-day storage window is separate from the 30-day timeline in 6. Data Retention: that is how quickly we act on an erasure request; this is how long we keep the audio if you do not make one.) The resulting transcript is kept alongside the order. You can revoke microphone permission for the App at any time in device settings; WhatsApp voice notes are governed by WhatsApp's own permissions on the customer's device.
2.6 Location Data
We collect location (GPS) data only from field sales representatives using the field-force features of the App: live location during active shifts, attendance check-in/check-out, and customer-visit check-ins. We do not collect location data from shop owners, cashiers, or customers who are not using field-rep features.
2.7 Data We Do NOT Collect
- We do not access your contacts
- We do not collect biometric data
- We do not serve ads or share data with advertising networks
3. How We Use Your Data
| Data | Purpose |
|---|---|
| Account data | Authentication, account recovery |
| Business data | Core POS functionality (billing, inventory, reports) |
| Customer data | Checkout, credit accounts, receipt sharing |
| Device token | Push notifications for new orders and alerts |
| Technical data | Bug fixes, performance improvements |
We do not sell your data to third parties.
4. Data Storage & Security
- All data is stored on servers located in India.
- Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access is controlled by role-based permissions — employees see only what their role allows.
- We conduct periodic security reviews.
5. Data Sharing
We share data only in the following limited cases:
| Recipient | Reason |
|---|---|
| Firebase (Google) | Push notifications via FCM |
| Keycloak (self-hosted) | Authentication and session management |
| Payment gateway (if enabled) | Processing UPI/card payments |
| Legal authorities | Only when required by Indian law (IT Act 2000) |
| WhatsApp messaging provider (Twilio, YCloud, or Meta, depending on the shop) | Carries WhatsApp messages and voice notes between a customer and a shop |
| Speech-to-text / AI order-extraction provider (Groq, hosted in the United States, or Sarvam AI, hosted in India, depending on configuration) | Converts a voice order's audio into text and structured order data |
Beyond the recipients named above, we do not share your data with advertisers, data brokers, or other third parties.
6. Data Retention
- Active account data is retained for as long as your account is active.
- If you cancel your subscription, we keep your data for 90 days so you can return and pick up where you left off. After that window it is deleted, except where retention is required by law.
- If you ask us to delete your account, we process the request and delete your data within 30 days — you do not have to wait for the 90-day window above — except where retention is required by law (e.g., GST records under Indian tax law).
- Transaction records may be retained for up to 8 years for tax compliance purposes.
7. Your Rights
As a user, you have the right to:
Access
View the data we hold about you
Correct
Fix inaccurate data
Delete
Remove your account and associated data
Export
Get your data in CSV format
Withdraw Consent
Disable push notifications anytime via device settings
To exercise any of these rights, email: privacy@vokart.in
8. Children's Privacy
VoKart POS is intended for use by adults (18+) operating a business. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us at privacy@vokart.in and we will delete it promptly.
9. Push Notifications
We send push notifications to inform you about:
- New orders or pending voice orders
- Low stock alerts
- Payment and credit account updates
You can disable push notifications at any time in your device settings or in the App under Settings → Notifications.
10. Changes to This Policy
We may update this policy periodically. We will notify you of significant changes via:
- In-app notification
- Email to your registered address
Continued use of the App after changes constitutes acceptance of the updated policy.
12. Governing Law
This Privacy Policy is governed by the laws of India, including:
- Information Technology Act, 2000
- Digital Personal Data Protection Act, 2023 (DPDPA)
Any disputes arising from this policy shall be subject to the jurisdiction of courts in India.